2023 CVE Vulnerabilities

31,245 CVEs published in 2023.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2023-25600HIGH7.1An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, lead...
CVE-2023-22277HIGH7.8Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP...
CVE-2023-22317HIGH7.8Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP...
CVE-2023-22314HIGH7.8Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP...
CVE-2023-3663HIGH8.8In CODESYS Development System versions from 3.5.11.20 and before 3.5.19.20 a missing integrity check might allow an unau...
CVE-2023-3662HIGH7.3In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of bina...
CVE-2023-21412HIGH8.8User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgi” allowing for SQL injection...
CVE-2023-21411HIGH8.8User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary c...
CVE-2023-21410HIGH8.8User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code e...
CVE-2023-21407HIGH8.8 A broken access control was found allowing for privileged escalation of the operator account to gain administrator priv...
CVE-2023-38748HIGH7.8Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a ...
CVE-2023-38747HIGH7.8Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. ...
CVE-2023-38746HIGH7.8Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By...
CVE-2023-38744HIGH7.5Denial-of-service (DoS) vulnerability due to improper validation of specified type of input issue exists in the built-in...
CVE-2023-4126HIGH8.8Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
CVE-2023-4125HIGH8.8Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
CVE-2023-39144HIGH7.5Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
CVE-2023-34196HIGH8.2In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of...
CVE-2023-38956HIGH7.5A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files v...
CVE-2023-38955HIGH7.5ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, ...
CVE-2023-36255HIGH8.8An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrar...
CVE-2023-36212HIGH8.8File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file...
CVE-2023-4078HIGH8.8Inappropriate implementation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ...
CVE-2023-4077HIGH8.8Insufficient data validation in Extensions in Google Chrome prior to 115.0.5790.170 allowed an attacker who convinced a ...
CVE-2023-4076HIGH8.8Use after free in WebRTC in Google Chrome prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap ...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now